Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pnobels
New Contributor III

Quick way to deny large ip list access

Hi,

 

recently we viewed in our logs a large number of attempts to gain remote access from a bunch of different ip addresses.  In Checkpoint it's possible to quickly block a large amount of ip addresses by doing something like 'fwaccel dos deny -l filename'.

 

Is there something similar in Fortigate (Forti Manager)?  We're running 7.0.12 btw.

__PRESENT

1 REPLY 1
AEK
SuperUser
SuperUser

Hello

May be one of the possible solution is the IP threat feed (you need to host it on some web server):

https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/891236/ip-address-threat-fee...

 

On other solution, if these IP addresses are known as bad IPs, to create a firewall rule to deny traffic from "ISDB > Sources with reputation 1".

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors